Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Startup aims to keep network security vendors honest

By Robert McMillan , IDG News Service , 03/28/2007

With the help of one of the world's best-known hackers, a little-known Austin startup hopes to give Internet service providers and enterprises a way to tell if their networking hardware is living up to its promises.

Late next month, BreakingPoint Systems Inc. plans to launch a new network test appliance that sniffs out security holes in devices like load balancers, intrusion prevention systems and routers. Called the BPS-1000, the device also gives users a way to see how their networking equipment performs under a high volume of networking traffic, said Dennis Cox, BreakingPoint's chief technology officer.

Cox and cofounder Craig Cantrell came up with the idea for BreakingPoint two years ago while working at 3Com Corp.'s TippingPoint division, where they realized that they were spending more money on testing equipment than they were on building products. What began as a running joke "every time we had to sign a purchase order for a half-million dollars worth of test equipment," eventually became a business plan, Cox said.

That vision is to build a product that gives customers an accurate picture of how their networking gear will behave in the real world -- before the bad guys have a chance to attack.

Shortly after the company was founded in September 2005, Cox hired HD Moore, maintainer of the popular Metasploit security testing tool. "He was one of the first guys I called up," said Cox. "There is no better person in the U.S. to break things than HD."

Today BreakingPoint has over 30 employees, including three security researchers who work with Moore to help develop BreakingPoint's security testing capabilities. Their job is to "do only evil," Cox joked, a play on Google's "Don't be evil" corporate motto.

While BreakingPoint's appliance does not use any of the Metasploit code, the company is leveraging Moore's expertise as a bug finder to offer customers a service called Strike Pack, which tests to see if about 2,500 attacks -- some of which have not yet been publicly reported -- are blocked on the network.

Over the past two weeks, BreakingPoint has already begun shipping its first few systems to network equipment makers, who are using it to test their own products, but Cox says that his company is also talking to enterprise customers -- particularly in the Internet and financial services markets.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Magic Quadrant for Application Delivery Controllers

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

The ROI and TCO Benefits of Data Deduplication for Data Protection in the Enterprise

This paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Webcasts

Transforming the Enterprise WAN Edge: Video from Cisco

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.